
pywhisker
Python version of the C# tool for "Shadow Credentials" attacks

Python version of the C# tool for "Shadow Credentials" attacks

Active Directory password filter featuring breached password checking and custom complexity rules

Pure-Python toolkit for Kerberos-based attacks including ASREProast, SPNroast, and LDAP enumeration to identify and exploit vulnerable Active…

F5 BIG-IP RCE exploitation (CVE-2022-1388)

Dump Kerberos tickets from the KCM database of SSSD

Tool to spray AWS Console IAM Logins

This repository contains the results of my August 2020 research of Tiandy's IPC/NVR firmware. I found two vulnerabilities that could be used to…


Authentication Bypass PoC for CVE-2025-2825 – Exploiting CrushFTP 10.x

Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

Client Implementation for the WatchGuard SSO Agent Protocol used for Security Research (CVE-2024-6592, CVE-2024-6593, CVE-2024-6594)

Proof of concept for CVE-2015-0006. Fixed in MS15-005 https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2015/ms15-005 .

PoC for login with password hash in STARFACE

Two POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.


Shell script for testing the IPMI cipher type zero authentication bypass vulnerability (CVE-2013-4784)